Information Security & Cybersecurity Engineer I/II/III/IV 015276

Univera Healthcare · Brooklyn NY

Company

Univera Healthcare

Location

Brooklyn NY

Type

Full Time

Job Description

Summary

The Information Security & Cybersecurity Engineer role develops, maintains, and coordinates the Organization's information security activities in support of the Lifetime Healthcare Companies' information security program. This position provides technical information security risk management and compliance services and support to the Organization's lines of business and further provides information security consulting and support to all levels of the Organization's management in support of the information security program. The cybersecurity disciplines range from Security Operations, Governance Risk and Compliance services, or Identity and Access Management.

  • Responsible for the design, implementation, and operation of Organization-wide security infrastructures. Evaluates and proposes new security solutions and advises and consults with the security manager and various levels of management regarding protection of computing resources and information assets.
  • Assists in the maintenance and operational support for security technologies in defense against modern cybersecurity threats
  • Delivers support for the Organization's Information Security Framework and strives to improve maturity of the Information Security program in certain Framework domains.
  • Respond to requests within defined SLAs relating to various information security systems, programs, and processes.
  • Maintains risk management documentation to monitor lifecycle progress, track acceptance decisions, and catalog remediation actions.
  • Utilizes automated Governance, Risk, and Compliance tools to track artifacts of the risk management lifecycle.
  • Enforces information security policies, standards, and procedures by administering and monitoring security reports; investigates possible security exceptions.
  • Delivers information risk management services for new and existing Enterprise Information Technology (EIT) automation products and projects.
  • Participates in rotation of 24/7/365 on call coverage.
  • Assists in the execution of HIPAA, MAR, PCI, and COBIT compliance activities.
  • Integrates security tools and appropriate controls into new and existing systems and applications.
  • Collaborates with the Networking, Information Management, and Web Development groups to ensure an appropriate level of security controls is "baked into" our infrastructure and applications.
  • Consults with information systems owners to categorize systems; select, implement, and assess controls; and frame, assess and monitor risk.
  • Assists in department self-audits, internal audits, external audit reviews, and risk assessments for EIT and for end user departments.
  • Participates in EIT security assessment of supplier and vendors develops recommendations to improve security and mitigate security risks.
  • Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies' mission and values, adhering to the Corporate Code of Conduct and Leading to the Lifetime Way values and beliefs.
  • Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures.
  • Regular and reliable attendance is expected and required.
  • Performs other functions as assigned by management.


(in addition to Level I essential responsibilities/accountabilities):

  • Works independently, at times, to support the Organization to deliver support for the Organization's Information Security Framework.
  • Keeps abreast of cyber threat landscape and evolving mitigation approaches and techniques.
  • Performs as the Subject Matter Expert for at least one information security technology, processes, and practices internally to the Health Plan - including making recommendations relating to this technology.
  • Provides technical expertise and support to security administrators on distributed systems security and implements automated solutions for security administration requests.
  • Trains and provides technical support to Security Administrators and lower-level InfoSec & Cybersecurity Engineers on distributed system and application security.
  • Provides consultation and facilitation support services to the Organization and its subsidiaries in information security matters and ensures compliance with the Organization's information security policies and standards.
  • Integrates security tools and appropriate controls into new systems and applications.
  • Acts as a security consultant for Organization's IT platforms, databases, middle-wares, and messaging systems (with oversight from a more senior analyst)


(in addition to Level II essential responsibilities/accountabilities):

  • Works independently to support the Organization to deliver support for the Company's Information Security Framework.
  • Performs as the Subject Matter Expert for at least two information security technology, processes, and practices internally to Health Plan.
  • Designs, develops, integrates, tests, evaluates, and maintains cybersecurity technology products.
  • Researches, engineers, and integrates new security solutions with an emphasis on solutions that aligns with overall cybersecurity strategy.
  • Performs cyber defense incident triage, including determining scope, urgency, and potential impact, and identifying the specific vulnerability.
  • Provides security consulting to business partners to ensure solution designs are aligned with security principles and cybersecurity frameworks.
  • Creates and implements security solutions that are compliant with the Lifetime Healthcare Companies architectural standards.
  • Mentors and trains lower-level staff.


(in addition to Level III essential responsibilities/accountabilities):

  • May act as Team Leader in management's absence.
  • Performs as the Subject Matter Expert for more than three information security technologies, processes, and practices internally to the Health Plan, and externally in the industry as a whole.


NOTE:We include multiple levels of classification differentiated by demonstrated knowledge, skills, and the ability to manage increasingly independent and/or complex assignments, broader responsibility, additional decision making, and in some cases, becoming a resource to others. In addition to using this differentiated approach to place new hires, it also provides guideposts for employee development and promotional opportunities.

  • Bachelor's degree in Computer Science, Information Technology, or relevant field with a minimum of one (1) year of related work experience preferred. In lieu of degree, six (6) cumulative years of related experience required.
  • Hands on experience with the following operating systems preferred: mainframe, Windows, and UNIX (Linux, AIX, Solaris, etc.).
  • Basic knowledge of a minimum of one concept and/or tool listed below:
    • Encryption
    • PKI
    • Network and application security, and related firewalls (Palo Alto Networks, Imperva, etc.)
    • AD, LDAP, and various authentication implementations
    • Virus detection and end point security (McAfee preferred)
    • Vulnerability scanner and pen testing tools (e.g., Rapid 7, Nessus, Nexpose, Metasploit, Appscan, Burp suite, Ida Pro etc.)
    • IDS/IPS and related tools
    • SIEM and tools (e.g., ArcSight, Splunk, SolarWind LEM, QRadar, McAfee, etc.)
    • Common web application security vulnerabilities (e.g., OWASP top ten)
  • Excellent verbal communications skills and concise written communication skills.
  • Excellent organization and multi-tasking skills.
  • Able to work both independently and as part of a team.


Level II:

All qualifications of Level I, as well as the following:

  • Three (3) of related work experience, and basic knowledge of a minimum of two (2) concepts and/or tools listed above (under Level I).
  • Experience with security controls for operating systems, applications, and database management systems.
  • Experience in evaluating security software packages.
  • Experience with security automation, including associated reporting and notification.
  • Knowledge of network regulations, industry standards and operational constraints of networks systems.


Level III:

All qualifications of Level II, as well as the following:

  • Five (5) years of related work experience, and basic knowledge of a minimum of three (3) concepts and/or tools listed above (under Level I).
  • CISSP, CISA, CISM or other relevant security certification, or equivalent experience, and knowledge preferred.
  • Experience providing work direction for one or more individual's specific projects and initiatives.
  • Experience providing guidance and mentorship to more junior team members.
  • Knowledge of Security Frameworks and translating aspects into enhancing security postures.


Level IV:

All qualifications of Level III, as well as the following:

  • A minimum of seven (7) years of related work experience, and basic knowledge of a minimum of four (4) concepts and/or tools listed above (under Level I).
  • Two (2) years demonstrated expertise in at least three (3) concentrations within information security technology.
  • Experience with creating and managing security architecture.


Physical Requirements

  • Ability to complete work in a traditional office environment under fluorescent lighting.
  • Ability to orally communicate.
  • Must be able to function while sitting at a desk viewing a computer and using a keyboard and mouse for 3 or more hours at a time.
  • Must be able to travel across the enterprise.
  • Ability to work in a home office for continuous periods of time for business continuity.
  • The ability to be on-call during non-business hours.


The Lifetime Healthcare Companies aims to attract the best talent from diverse socioeconomic, cultural and experiential backgrounds, to diversify our workforce and best reflect the communities we serve.

Our mission is to foster an environment where diversity and inclusion are explicitly recognized as fundamental parts of our organizational culture. We believe that diversity of thought and background drives innovation which enables us to provide leading-edge healthcare insurance and services. With that mission in mind, we recruit the best candidates from all communities, to diversify and strengthen our workforce.

OUR COMPANY CULTURE:

Employees are united by our Lifetime Way Values & Behaviors that include compassion, pride, excellence, innovation and having fun!We aim to be an employer of choice by valuing workforce diversity, innovative thinking, employee development, and by offering competitive compensation and benefits.

In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position.

In support of the Americans with Disabilities Act, this job description lists only those responsibilities andqualifications deemed essential to the position.

Equal Opportunity Employer

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)

Date Posted

11/10/2022

Views

18

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Software Engineer - Python - Vatic Investments

Views in the last 30 days - 7

Vatic Investments is looking for a Python Software Engineer to work on algorithmic trading systems The role requires expertise in C Python and Linux a...

View Details

Senior DevOps Engineer - 3Red Partners

Views in the last 30 days - 0

3Red Partners LLC is seeking a Senior DevOps Engineer to join their team The company offers competitive benefits excellent worklife balance and opport...

View Details

Senior Mobile Engineer - Viam

Views in the last 30 days - 13

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for a Mobile Engineer to build c...

View Details

Software Engineer - Viam

Views in the last 30 days - 14

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots It offers a modern architecture easy developer APIs clo...

View Details

Software Engineer, SDK/NetCode - Viam

Views in the last 30 days - 11

Viam is a robotics platform that makes it easy to turn great ideas into productionready robots The company is looking for engineers to build software ...

View Details

Sr. Manager/Associate Director, Program Management - Volastra Therapeutics

Views in the last 30 days - 11

Volastra Therapeutics is a biotechnology company dedicated to discovering and developing treatments for patients with cancer They have raised funding ...

View Details